CVE-2026-27456: util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup

Overview

Severity
Medium (CVSS 4.7)
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U
Exploit Status
Not Exploited
Patch Tuesday
2026-Apr
Released
2026-04-05
Last Updated
2026-04-14
EPSS Score
0.02% (percentile: 4.4%)

Affected Products (3)

Open Source Software

  • azl3 util-linux 2.40.2-3 on Azure Linux 3.0
  • cbl2 util-linux 2.37.4-10 on CBL Mariner 2.0
  • azl3 util-linux 2.40.2-4 on Azure Linux 3.0

Revision History

  • 2026-04-05: Information published.
  • 2026-04-06: Information published.
  • 2026-04-07: Information published.
  • 2026-04-07: Information published.
  • 2026-04-14: Information published.
  • 2026-04-14: Information published.